A hard deadline meets a soft rollout
On 18 August 2026, Regulation (EU) 2023/1543 becomes directly applicable across the European Union, replacing the old Mutual Legal Assistance Treaty process — which the European Commission says can take up to 10 months — with a mechanism that lets a judicial authority in one member state order a service provider in another to hand over subscriber, traffic, or content data directly. Standard orders must be executed within 10 days; emergency orders within 8 hours. There is no dispute about the goal: criminal investigations increasingly hinge on data held by providers outside the investigating country, and a decade-old assistance regime built for paper requests and postal timelines is a genuine bottleneck for prosecutors chasing perishable digital evidence.
The problem, according to EuroISPA — the European trade association representing internet service providers — is that the law is arriving on schedule while everything meant to support it is not. In a June 2026 statement, the group warned that "most Member States have yet to fully transpose" the companion Directive (EU) 2023/1544, that the EU's decentralised IT system for routing orders "remains under development," and that industry estimates put the build time providers need from finalized technical specifications at 18 months — specifications that, as of the warning, had not been finalized anywhere in the bloc.
The transposition gap is not close
The numbers back up EuroISPA's alarm. The Directive's transposition deadline was 18 February 2026. On 27 March 2026, the Commission sent letters of formal notice — the first stage of an infringement procedure — to roughly 22 member states for failing to communicate full transposition, according to a summary from Global Regulation Tomorrow. By February 2026, only a handful of countries — Croatia, Italy, Lithuania and Slovakia — had adopted implementing legislation, with Germany following in March. That leaves the large majority of the EU legislating against its own deadline while the Regulation's clock, which does not wait for national transposition, keeps running toward 18 August.
This matters because the Regulation and Directive are meant to function as one package. The Regulation creates the direct order power; the Directive obliges member states to appoint the legal representatives, enforcement authorities, and penalty regimes that make the order power enforceable and appealable. A provider served with an emergency order in a state that hasn't finished transposing has no settled national counterpart to confirm procedure against — precisely the ambiguity a harmonizing law was supposed to eliminate.
Steelmanning the urgency
It would be a mistake to treat this purely as regulatory overreach. Law enforcement's underlying complaint is legitimate: criminals already exploit jurisdictional friction, routing communications through providers headquartered in whichever member state offers the slowest cooperation channel. An 8-hour emergency window for cases involving imminent threats to life is not disproportionate on its face — most major platforms already operate voluntary emergency-disclosure programs on comparable timelines. The Regulation's core bet, that a harmonized direct-order system beats a patchwork of bilateral MLATs, is defensible policy, not a civil-liberties overreach — it was negotiated with data-protection and judicial-review safeguards built in, including notification to the enforcing state for content data.
Where proportionality breaks down
The failure here isn't the policy; it's sequencing. Regulators are entitled to demand fast compliance once the infrastructure to comply exists. They are not entitled to start the enforcement clock while withholding the technical means of compliance. EuroISPA's June statement asked the Commission for four specific things: a grace period tied to actual system readiness rather than the calendar date, resolution of scope inconsistencies between the Regulation and Directive, recognition that cross-border providers can designate a single compliance hub rather than one per member state, and protection from penalties for providers acting in good faith against infrastructure that isn't there. None of these asks weaken the law's substance — they ask Brussels to make the mechanism it built actually usable before punishing people for failing to use it.
The providers most exposed are not the largest platforms, which can absorb compliance uncertainty and legal risk as a cost of doing business, but the small and mid-sized hosting and communications providers EuroISPA represents — the ones least equipped to build parallel compliance workflows for 27 different national enforcement regimes on six weeks' notice.
The proportionate fix is procedural, not substantive
A regulation that compels 8-hour responses should not itself take years to become operational through improvisation. The Commission does not need to reopen the underlying policy debate to fix this — it needs to either delay application until the decentralised IT system and national transposition are verifiably functional, or explicitly shield good-faith non-compliance caused by the EU's own missing infrastructure. Enforcing a deadline the enforcer's own member states can't meet doesn't demonstrate seriousness about cross-border crime; it just transfers the EU's implementation risk onto the companies caught in the middle.